CVE-2025-11844 is an XPath injection vulnerability in Hugging Face Smolagents versions prior to 1.22.0, specifically within the search_item_ctrl_f function. This flaw allows an unauthenticated attacker to inject malicious XPath syntax via user-supplied input, bypassing search filters and accessing unintended DOM elements. Rated Medium severity (CVSS 5.4), the vulnerability requires user interaction (UI:R) but has low attack complexity (AC:L), potentially leading to information disclosure and manipulation of AI agent interactions. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.20.0, < 1.22.0CPE matchmatch criteria | cpe:2.3:a:huggingface:smolagents:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.